Privacy Policy
SuiteMate is job-management software for trade and construction businesses. This policy explains what personal information we collect, why we collect it, who we share it with, and what you can do about it. It is written to be read, not to be survived.
1. Who we are
SuiteMate is operated by Fermiware Pty Ltd (ABN 78 699 924 475), an Australian proprietary limited company registered in New South Wales. In this policy, "we", "us" and "our" mean Fermiware Pty Ltd, and "SuiteMate" means our web application at app.suitemate.com.au and our website at suitemate.com.au.
Our registered office is 7 Conley Avenue, Lake Conjola NSW 2539, Australia.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Some small businesses are exempt from the Privacy Act, but we have chosen to comply regardless, because our customers trust us with information about their own clients and workers.
2. Two different roles โ and why it matters
SuiteMate handles two quite different categories of information, and our obligations differ for each. This distinction runs through the rest of this policy, so it is worth getting straight up front.
| Category | Example | Our role |
|---|---|---|
| Account information | Your name, email, company details, billing records | We decide how it is used. We are the controller. |
| Customer data | Your clients, your workers, your quotes, your job sites | You decide how it is used. We only hold and process it on your instructions. We are the processor. |
In plain terms: the records you put into SuiteMate remain yours. We do not sell them, mine them, or use them to build products. If one of your clients asks us what we hold about them, we will direct them to you, because you are the business they dealt with โ not us.
3. What we collect
3.1 Account and identity information
- Name, email address and password (stored only as a cryptographic hash โ we never see or store your actual password)
- Business name, ABN, trading address, phone number
- Your role within the business, and which features you are permitted to use
- Login timestamps and session records
3.2 Billing information
- Subscription status, plan, seat count and renewal dates
- Invoices and payment history relating to your SuiteMate subscription
- A Stripe customer identifier linking your account to your payment record
We never see or store your card number. Card details are entered directly into Stripe's hosted checkout and never touch our servers. We receive only a token and the last four digits.
3.3 Customer data you enter
This is the substance of what SuiteMate stores, and it is genuinely sensitive โ it describes other people, most of whom have no direct relationship with us:
- Clients and contacts โ names, email addresses, phone numbers, billing and site addresses
- Workers and subcontractors โ names, contact details, emergency contacts, employment status, pay and charge rates, cost types
- Payroll details โ a worker's bank account name, BSB and account number, their superannuation fund and member number, and their tax file number with its declaration details (basis of payment, residency status for tax purposes, tax-free threshold and study-loan answers), entered by the worker or the office so wages can be paid and tax withheld correctly. These are stored separately from ordinary records and are visible only to the worker themselves and to the business's owners and admins โ the rest of the crew cannot see them. Tax file numbers are handled in line with the Privacy (Tax File Number) Rule 2015: we use them only for payroll and tax purposes, never disclose them except as tax law requires, and delete them with the rest of your data when your account is deleted.
- Licences and tickets โ licence types, numbers and expiry dates recorded against a worker
- Timesheets โ hours worked, dates, and which job they were worked on
- Jobs and projects โ site addresses, scopes, statuses, priorities and scheduled dates
- Quotes and invoices โ line items, measurements, costs, discounts, approval status and payment status
- Schedules โ who is assigned where, and when
- Messages and communications โ email and SMS sent through SuiteMate, in-app chat between members of your team, and message threads with connected businesses
- Purchase orders โ including orders sent to and received from other SuiteMate businesses
- Attachments and files โ plans, photographs, checklists, site documents and purchase-order attachments
- Assets and inventory โ equipment records and stock levels
3.4 Technical information
- IP address, browser type and device information
- Server and application logs, including error reports and diagnostic traces
- Pages visited and actions taken within the application, for security auditing and troubleshooting
3.5 Mobile app information
The SuiteMate mobile app collects three things the website does not. Each one is asked for at the moment it is needed, and each can be refused.
- Location โ when a worker clocks on or off, the app records the device's location at that moment so the business can confirm the hours were worked on site. This is a single reading taken at the tap. SuiteMate does not track anyone in the background, does not follow a device between jobs, and collects nothing while the app is closed. If location permission is declined, clocking on still works โ the entry is simply saved without coordinates.
- Camera and photo library โ only when a worker chooses to attach a photo to a job or a form. The app reads the image selected and nothing else in the library.
- Push notification token โ an anonymous device identifier issued by Apple or Google so SuiteMate can notify a worker that they have been rostered onto a job. It identifies the device, not the person, and is deleted when the app is uninstalled or the worker signs out.
Clock-on locations are visible to the business that employs the worker โ that is the point of recording them. They are not shared with anyone else, and they are never sold or used for advertising. The app contains no advertising, no analytics profiling and no cross-app tracking.
3.6 Sensitive information
We do not ask for sensitive information as defined by the Privacy Act (such as health, racial or ethnic origin, political opinions, religious beliefs, or criminal record). SuiteMate has no fields designed to hold it.
However, free-text fields โ job notes, checklist notes, messages โ will accept whatever is typed into them. Please do not record sensitive personal information in free-text fields, such as a worker's medical details or an incident involving someone's health. If you need to store that kind of record, use a system built for it.
4. How we collect it
- Directly from you โ when you sign up, configure your account, or enter records
- From your team โ when other users in your business use the app
- From connected businesses โ when another SuiteMate business sends you a purchase order or links with you, limited to what that feature shares
- From integrations you authorise โ for example, contacts and invoices synchronised from Xero when you connect it
- From the mobile app on a device โ a location reading at clock-on, a photo you choose to attach, and a push notification token, each only after the device has asked your permission (see 3.5)
- Automatically โ technical and log information generated as you use the service
- By email โ where you use a SuiteMate inbound email address to forward documents such as purchase orders
Where we collect information about a person from you rather than from them โ your clients and your workers, for instance โ you are responsible for having told them that you use a system like SuiteMate, and for having any consent required. We provide the tooling; the relationship is yours.
5. Why we use it
We use personal information only for purposes connected with running the service:
- To provide SuiteMate's features โ quoting, scheduling, timesheets, invoicing, messaging and reporting
- To authenticate you and keep your account secure
- To calculate and collect your subscription, including counting active people for per-person billing
- To send transactional messages on your behalf โ quotes, invoices, reminders and purchase orders โ to recipients you nominate
- To send you service messages about outages, security matters, billing and material changes
- To provide support, and to investigate faults you report
- To detect, prevent and investigate fraud, abuse and security incidents
- To meet our legal, tax and accounting obligations
- To improve the product, using aggregated and de-identified usage patterns
What we do not do: we do not sell personal information. We do not share it with advertisers or data brokers. We do not use your customer data to train machine-learning models. We do not read your records except where strictly necessary to fix a fault you have reported, respond to a security incident, or comply with the law.
6. Who we share it with
SuiteMate is built on infrastructure operated by other companies. Each is bound by its own contractual and privacy obligations, and each receives only what it needs.
| Provider | Purpose | What it receives |
|---|---|---|
| Supabase | Database, authentication and file storage | All application data, including customer data and attachments |
| Vercel | Application hosting and delivery | Requests, IP addresses and server logs |
| Stripe | Subscription billing, and card payments on your invoices where you enable them | Billing contact details and payment records. Card data goes directly to Stripe. |
| Resend | Sending email | Recipient addresses and the content of messages sent through SuiteMate |
| Twilio | Sending SMS | Recipient mobile numbers and message content |
| Xero | Accounting synchronisation, only if you connect it | Contacts, invoices and payment records you choose to sync |
| Fair Work Commission API | Retrieving current award pay rates | Award and classification lookups only โ no personal information |
| Australian Business Register | ABN validation | ABN lookups only |
We may also disclose personal information:
- To another SuiteMate business you deliberately connect with, limited to what the connection feature shares โ principally purchase orders, their line items, attachments, message threads, and the scheduled date and time of accepted work
- To professional advisers such as accountants and lawyers, under confidentiality
- Where required by law, court order, or a properly authorised request from a regulator or law-enforcement agency
- To a purchaser or successor if the business is sold or restructured, in which case we will notify you and the acquirer will be bound by terms no less protective than these
7. Overseas disclosure
Your application data โ including all customer data โ is stored in Sydney, Australia (AWS ap-southeast-2).
Some of our providers are headquartered overseas, principally in the United States, and their support and engineering staff may access systems from outside Australia. In particular, Stripe, Resend, Twilio, Vercel and Xero each operate internationally. By using SuiteMate you consent to this disclosure. We take reasonable steps to ensure each provider handles information consistently with the Australian Privacy Principles, but we cannot control every practice of an overseas recipient, and APP 8.1 may not apply to all of them.
8. Where it lives and how it's protected
We take security seriously, and some of the measures are structural rather than merely procedural:
- Tenant isolation at the database level. Every table enforces row-level security keyed to your company. A query from your account is physically incapable of returning another business's rows, regardless of what the application code does. This is enforced by the database, not by the app.
- Encryption in transit โ all traffic uses TLS.
- Encryption at rest โ data and file storage are encrypted by our hosting provider.
- Password hashing โ passwords are stored only as salted hashes and cannot be reversed.
- Scoped file storage โ uploaded files are stored under paths bound to your company, and access is checked on every request.
- Least-privilege access โ staff access to production data is limited to what is needed to operate the service, and is used only for the purposes described in section 5.
- Secrets management โ API keys and credentials are held in encrypted environment storage, never in source code.
No system is perfectly secure, and we will not pretend otherwise. If you discover a vulnerability, please report it to us โ see section 15. We will not pursue action against anyone who reports a genuine security issue in good faith and does not exploit it or access other users' data.
9. How long we keep it
- While your account is active โ we keep your data for as long as you use SuiteMate.
- If your subscription lapses โ SuiteMate becomes read-only rather than locking you out. Your records stay visible and exportable. We do not delete or ransom your data because a payment failed.
- After you close your account โ we retain your data for 90 days so you can change your mind or complete an export, then delete it from production systems.
- Backups โ deleted data may persist in encrypted backups for up to 35 days before being overwritten.
- Financial records โ invoices and payment records relating to your subscription are kept for seven years, as Australian tax law requires. This applies even after account closure.
10. Your rights
Under the Australian Privacy Principles you may:
- Access the personal information we hold about you
- Correct anything inaccurate, out of date or incomplete
- Export your data โ SuiteMate includes a full export function, and it keeps working even if your subscription has lapsed
- Delete your account and data, subject to the retention periods in section 9 โ see how to request deletion
- Complain if you believe we have mishandled your information
- Opt out of non-essential email. Service messages about security, billing and outages cannot be opted out of while you hold an account.
Most of these you can do yourself inside the app. For anything else, contact us and we will respond within 30 days. We do not charge for access requests. If we refuse a request, we will tell you why in writing.
If you are a client or worker of a SuiteMate customer โ that is, your details are in the system because a business you dealt with put them there โ please contact that business directly. They control those records. We will assist them in responding, but we cannot alter or release their data on your behalf.
11. Cookies and tracking
SuiteMate uses cookies and similar browser storage strictly for operation:
- Authentication โ to keep you logged in between pages
- Security โ to protect against cross-site request forgery
- Preferences โ to remember settings such as your chosen theme
We do not use advertising or third-party tracking cookies, and we do not run analytics that profile individuals across sites. Blocking essential cookies will prevent you logging in.
12. Data breaches
We are subject to the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. If a breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable.
Where the breach involves data belonging to one of our customers, we will notify that customer promptly and give them the information they need to meet their own notification obligations.
13. Children
SuiteMate is business software and is not directed at children. We do not knowingly collect information from anyone under 16 as an account holder. Where a customer records a young apprentice as a worker, that record is customer data under section 2 and the employing business is responsible for it.
14. Changes to this policy
We may update this policy as the product changes or the law does. The effective date at the top always reflects the current version. For material changes โ a new category of data, a new disclosure, a new overseas recipient โ we will give you at least 30 days' notice by email or in-app before the change takes effect.
15. Contact and complaints
To make a privacy request, ask a question, or report a security issue:
- Email โ info@suitemate.com.au
- Post โ Privacy Officer, Fermiware Pty Ltd, 7 Conley Avenue, Lake Conjola NSW 2539
We will acknowledge a complaint within 5 business days and respond substantively within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.